Bitlocker enabled itself on Windows 10 Home edition without a notice and without permission

Anonymous
2022-06-29T22:51:13+00:00

After three years of owning a Dell Inspiron 13 (Windows Home) the computer somehow enabled Bitlocker on its own and encrypted my C: drive. Since I did not activate Bitlocker, I don't have the keys to decrypt the drive. My Microsoft account does not list any keys in it so there is no way to recover the keys as far as I know. Therefore none of the published solutions I have seen can work because they all assume that I have access to the keys. I see many similar complaints online (at least since 2018) and hundreds of "likes" so this appears to be a relatively common problem.

When booting, I see a message titled "BitLocker recovery" and it asks for the recovery key. It then says to "try your work or school account at: aka.ms/aadrecoverykey."

This suggests that the key may be associated with some active directory domain away from my computer. However, the admin account on this computer has, to my knowledge, never logged into an active directory domain, although non-admin users have. And, if the Amin account has connected to a Active Directory somewhere, I sure as heck did not give them a permission to encrypt my drive and lock me out of my computer, and give the key to some third party "work or school" account. If this is what happened, Microsoft, you have a serious security issue where third parties can effectively encrypt hard drives without permission using Microsoft's own tools. That is ransomware - without the ransom. But, this is still just a theory vaguely supported by this link https://hardsoft-support.kayako.com/article/99-windows-10-bitlocker-turns-on-without-a-notice

Here is a quote from the post: "Dell and Lenovo systems that ship with the Windows 10 operating system and are equipped with Trusted Platform Module (TPM) capability will have Microsoft BitLocker encryption enabled from the factory. It has been found that once the device is registered to a Active Directory domain - Office 365 Azure AD, Windows 10 automatically encrypts the system drive. You find this once you reboot your computer and are then prompted for the BitLocker key."

Since I don't know what possible organization could have encrypted the drive, and since I don't have admin access to them, the instructions in the article don't apply.

The laptop is Dell Inspiron 13 7370 - which I don't even think has a TPM chip built in it. BIOS is version 1.20.0. ePSA build is 4306.13 UEFI ROM.

So, Microsoft, how does this get fixed?

P.S. My other computers have Win10 Pro and and they have Bitlocker turned on, but this computer intentionally did not have Bitlocker turned on - and it was not supposed to be possible to turn on bitlocker on a Win10 Home edition. I am mentioning this to highlight that I did not "accidentally" trigger the Bitlocker being turned on - especially because it requires many steps and confirmations. The drive was simply encrypted one day with permission from me.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

104 answers

Sort by: Newest
  1. Anonymous
    2024-02-21T23:08:24+00:00

    as i repeat all the info for the 3rd time in this forum

    Only disability is your understanding,

    its by design now in modern windows Home and some pro OEM pc's, if you log in with a microsoft account it turns it on automatically Yet It will Save the Key on Microsoft site in your account. .

    so only way is to TURN TPM OFF in BIOS or encryption in windows settings, that it, move on. that is what TPM does, its for encryption.

    your recover KEY if you get locked out is in attached to your microsoft account accessible on any device, .

    see link in here that says In your Microsoft account.

    Finding your BitLocker recovery key in Windows - Microsoft Support (if this link no longer works , google it is all)

    and ya if you dont now how to log into your microsoft email account on another computer , then thats your problem at this point. or if was setup on a previous account on that device, then ya , option is to format

    and know what to do going forward,, ie ,learn how to manage and remember to log into your microsoft account on any device , or TURN TPM OFF in BIOS. Thats all ,

    Windows 11 Home is now designed to login with Microsoft account so you have to turn it off even if you bypass windows default process, ......., NEXT

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Neil D 34,285 Reputation points Volunteer Moderator
    2024-02-21T22:40:39+00:00

    It does (as you say) enable during setup and it is Device encryption, which is using BitLocker. It may not be the classic BitLocker as in Pro edition but Home edition can have the system drive encrypted during he OOBE.

    The device manufacturers know about this (in my opinion) should let the new user know that it occurs and the way to check for the recovery key, while they can or the method to turn it off.

    While the system is accessible it can be turned off in Settings > Privacy & security > Device encryption.

    If a user has a Microsoft account and used that during setup then the recovery key should be visible in their account.

    Neither Microsoft nor the device manufacturer seem to give a new user that information.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-02-21T16:31:24+00:00

    There seems to be a learning disability with some of the replies on here.

    We know how to disable bitlocker, that is not the issue.

    The issue is that bitlocker is activating itself and without a key available.

    It seems there is no recovery at all from this.

    Why are some suggesting turning it off, yet it was never on?

    Why are some suggesting finding your key so you can recover, when there was no key?

    These people appear not to understand plain English.

    Bitlocker is activating itself without a saved key and this does happen on 'home' versions.

    Sorry but there is no way out of this other than a format and start again.

    It appears you cannot even removed the bitlocker software.

    Microsoft need to address this issue, it is no use saying that it cannot happen when it clearly does, and its no use saying it is not on Home edditions as it clearly is.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-02-17T19:25:17+00:00

    its also funny that there is so much false information on this on the web, i found this HP document explaining some , but not why, i read somewhere before Microsoft recomended it to OEM's so they did it,

    also 10 and 11 is the same OS under the hood so , it applies to 10 and 11 , just older article.

    HP PCs - BitLocker encryption is enabled by default (Windows 10) | HP® Support

    has its says what happened to you ,but if was off i dont know, mabey you needed clear tpm data in bios , that would make sence why it asked even if off in the OS,

    NOTE: The BitLocker recovery key is needed to perform updates that affect the TPM data, including BIOS updates.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2024-02-17T15:20:56+00:00

    after install I know disable secureboot and TPM in the bios problem solved, encryption needs them on.

    Was this answer helpful?

    0 comments No comments